Bloginator · Bloginator · CVE-2009-1049
**Name of the Vulnerable Software and Affected Versions**
Bloginator version 1A
**Description**
A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the `id` parameter in the articleCall.php file.
**Recommendations**
For Bloginator version 1A, avoid using the `id` parameter in the articleCall.php file until a fix is available. As a temporary workaround, consider restricting access to the articleCall.php file to minimize the risk of exploitation.